vx-underground
47.3K subscribers
4.07K photos
436 videos
84 files
1.48K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
As part of the vx-underground x @SentinelOne Malware Research Challenge, DLL_Cool_J released a paper on state sponsored Threat Actors targeting security researchers by weaponizing tools such as Ghidra.

This paper also provides historical examples.

https://www.sentinelone.com/blog/analyzing-attack-opportunities-against-information-security-practitioners/
πŸ‘23❀7πŸ”₯5
We spoke with an AI and Machine Learning scientist. His work includes novel cancer detection methods using machine learning and scalable finite difference methods for reinforcement learning.

AI is a hot topic. We'll be discussing AI in regards to cyber weaponry with him.
πŸ”₯78πŸ‘6πŸ‘4😁1
Behind the scenes at vx-underground (ignore the cat).
🀣180πŸ₯°20🫑14πŸ€ͺ9😁6πŸ€”6πŸ‘3❀2πŸ”₯2πŸ™2πŸŽ‰1
NoBit ransomware group states they encrypt data in SHA 😭😭😭
🀣209πŸ€ͺ10πŸ‘6😒3❀2πŸ€”2πŸ‘1🀩1πŸ’―1
NoBit contacted us regarding this message. They state we have misunderstood their post.
🀣186πŸ‘17😁12πŸ€ͺ11😒6🫑4❀‍πŸ”₯3πŸ€”2🀯1🀩1
How do you pronounce "CVE"?

1. C. V. E.

2. Svye

3. KaVooEe
πŸ€”91🀣65πŸ’―14🫑12😘5πŸ‘3🀯3❀‍πŸ”₯2😁2πŸ”₯1πŸ™1
Today ALPHV ransomware group gave us their autograph.

The administrators English penmanship is better than we expected
πŸ”₯79🀣43πŸ‘9😍6
People have been discussing the "death" of infosec Twitter. They have defined it's decline based on the number of KaVooEe's discussed each month.

Infosec is more than just KaVooEe's.
🀣72πŸ‘7❀2
Telegram is the only platform that vx-underground utilizes that can generate a 250% increase of web traffic and post engagement if we share images of cats.
πŸ€ͺ226πŸ₯°78🫑44❀26🀣20πŸ‘15πŸ’―9😍8❀‍πŸ”₯7πŸ”₯7πŸ‘6
We've updated the vx-underground malware source code collection on GitHub

- Javascript.Kaoom.Unknown
- Panel.BlackHole.IonCube.a
- Win32.GreenDamCensor.Exploit.a
- Win32.Bootkit.BlackLotus.b

https://github.com/vxunderground/MalwareSourceCode
❀29❀‍πŸ”₯7πŸ‘6😱2🫑1
A money mule cashing out for a Threat Actor (2023, colorized)
🀣124😍19😁8❀5πŸ‘3πŸ₯°3
Today David Grusch, an individual who served 14 years with the United States Air Force and National Geospatial Intelligence Agency, testified under oath that the United States government possesses 'Unidentified Anomalous Phenomena' and has been reverse engineering it for decades

More info: https://www.cbsnews.com/news/ufo-hearing-congress-uap-takeaways-whistleblower-conference-david-grusch-2023/
🀣48😱14πŸ‘7😁5🀯5πŸ”₯4❀2❀‍πŸ”₯1
Today haveibeenpwned announced they have acquired the Breached Forum database. An individual using the alias "breached_db" compromised Breached in November, 2022. This was when Pompompurin was the administrator.

This database leak exposes PII on 212,000 users.
😁57🀯19πŸ‘15😒8
cl0p ransomware group has compromised 3 of the largest Cyber Threat Intelligence agencies on the planet.

They have extorted schools, healthcare facilities, and multimillion dollar organizations.
πŸ”₯108🫑39πŸ€”12❀4😁4🀯3πŸ‘1πŸ‘1πŸŽ‰1
With Web Environment Integrity in Chromium (Chrome, Opera, Edge) it'll allow websites to determine whether a visitor is a human or a robot based off of hardware fingerprinting.

It is designed to enhance ad delivery capabilities.

https://twitter.com/nearcyan/status/1684242509847822336
πŸ€”42😱18😒16🀯8πŸ‘5🀣5🫑5❀2πŸ‘1πŸ’―1
In the past month nerds have been complaining of a worm on Activision's MW2 (2009)

A shared sample shows a sideloaded 32bit dsound.dll with some silly strings. It hooks DirectSoundCreate8 and then begins to work

We have only briefly skimmed the file. We'll share the sample
😱38πŸ‘10❀7πŸ€”3🀯1
The sample is available on the vx-underground website. It is located under /Tmp/

Hash: CB000ABED31B92B4F3F895A633EF0FFAF01A1BE0DFC73619ACF98C1605A5999D
❀24πŸ‘6❀‍πŸ”₯3😒2
We're in the process of re-verifying our APT sample and paper collection while simultaneously renaming directory structures to improve legibility.

Behold! It is beautiful =D
❀47πŸ”₯7πŸ₯°3πŸ€”2